Cyber Defense Advisors

News

  • by
  • November 15, 2022

Log4Shell-like code execution hole in popular Backstage dev tool

Researchers at cloud coding security company Oxeye have written up a critical bug that they recently discovered in the popular cloud development toolkit Backstage. Their report includes an explanation of how the bug works, plus proof-of-concept (PoC) code showing how to exploit it. Backstage is what’s known as a cloud developer portal – a sort […]

Cyber News, Cyber Threat Trends

Billbug Targets Government Agencies in Multiple Asian Countries

According to Symantec, the targeting of a certificate authority was notable

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2022

Stop Writing Paper Policies

ACM.112 A look at how effective your PDF and Word cybersecurity policy documents are in a cloud environment — and how to fix it This is a continuation of my series on Automating Cybersecurity Metrics. OK I’m being a little dramatic. We are not going to do away with all forms of traditional documentation, but please consider the […]

Cyber News, Cyber Threat Trends

Lazarus Backdoor DTrack Evolves to Target Europe and Latin America

DTrack has not changed substantially, but Lazarus made some “interesting” modifications

Cyber News, Cyber Threat Trends

Remote Code Execution Discovered in Spotify’s Backstage

Spotify ranked the vulnerability as critical, with a CVSS score of 9.8

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2022

Top Zeus Botnet Suspect “Tank” Arrested in Geneva

Vyacheslav “Tank” Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, according to multiple sources. Wanted Ukrainian cybercrime suspect Vyacheslav “Tank” Penchukov (right) was arrested in Geneva, Switzerland. Tank was […]

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2022

Meta’s new kill chain model tackles online threats

In April 2014, Lockheed Martin revolutionized the cyber defense business by publishing a seminal white paper Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains. This document sparked a new wave of thinking about digital adversaries, specifically, nation-state advanced persistent threat groups (APTs). The authors of the paper argued that […]

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2022

Global 2000 companies failing to adopt key domain security measures

Forbes Global 2000 companies are failing to adopt key domain security measures, exposing them to significant security risks, according to CSC’s Domain Security Report 2022. The enterprise-class domain registrar and Domain Name System (DNS) threats mitigator found that 75% of Global 2000s have implemented fewer than half of all domain security measures with Domain-based Message […]

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2022

Deep Packet Inspection vs. Metadata Analysis of Network Detection & Response (NDR) Solutions

Today, most Network Detection and Response (NDR) solutions rely on traffic mirroring and Deep Packet Inspection (DPI). Traffic mirroring is typically deployed on a single-core switch to provide a copy of the network traffic to a sensor that uses DPI to thoroughly analyze the payload. While this approach provides detailed analysis, it requires large amounts […]

Cyber News, Cyber Threat Trends